diff --git a/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf b/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf index 7f68f2a5..1d3fdf38 100644 --- a/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf +++ b/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf @@ -30,7 +30,9 @@ resource "azurerm_dns_cname_record" "custom" { resource "azurerm_dns_txt_record" "challenge" { for_each = { for k, v in var.custom_domains : k => v if v.tls.certificate_type == "ManagedCertificate" } - name = join(".", compact(["_dnsauth", replace(each.value.host_name, ".${each.value.dns_zone_name}", "")])) + # If the host name is the same as the zone name, then it's the apex domain + # Apex domain requires _dnsauth. Subdomains require _dnsauth.. + name = each.value.host_name == each.value.dns_zone_name ? "_dnsauth" : "_dnsauth.${each.value.host_name}" zone_name = each.value.dns_zone_name resource_group_name = each.value.dns_zone_rg_name ttl = 60